THE Italian Data Protection Authority has fined IQVIA Solutions Italy Srl €7 million following an investigation into a data protection breach. The authority found that IQVIA had created a database containing health information on around one million patients from 800 general practitioners, which was used for studies commissioned by pharmaceutical companies.
The data were not anonymous, as IQVIA’s coding allowed patients to be tracked over time, and when combined with highly detailed information such as year of birth, sex, diagnoses, prescriptions, tests, vaccinations, and even location data, it could be used to identify individuals.
The Authority determined that IQVIA acted as the data controller from the moment the data were collected from physicians and that the health data were processed without an adequate legal basis or proper patient information. Retention periods were not defined, with data dating back to 2001, and there was no required data protection impact assessment or sufficient security measures.
The dataset also contained identifying information—names, tax codes, addresses, and contact details—for more than 3,300 patients, with over 3,000 of those records linked to health data. The commission noted that transmissions by doctors had ceased from 2023, but the company was given 120 days to align its processing with the authority’s requirements or to ensure anonymisation by the doctors in accordance with the authority’s guarantees. The Rome press release is dated 2 October 2026.